Cloud Managed Networks

 View Only
  • 1.  Configure Uplink Auth for all APs of a VC

    Posted Jun 09, 2022 11:49 AM
    Hi all,

    with controllers I can configure the Uplink EAP-PEAP or EAP-TLS settings for the whole AP group but with Central it seems like I need to edit every single AP. Is that the only way or am I missing something?

    Right now I need to go into group level, List view, click the pencil of the AP, go to Interface -> Uplink and there I can enter the PEAP credentials. Then I need to go to AP level, go to config, Uplink and there enable PEAP as protocol. And these steps for every AP.
    My customer wants to configure this for a couple hundred APs in multiple groups, is there a simpler way to do this?

    And is there a way so that new APs automatically get this settings pushed when they join the VC?


    ------------------------------
    Thanks,
    Bjarne
    ------------------------------


  • 2.  RE: Configure Uplink Auth for all APs of a VC

    Posted Jun 09, 2022 08:03 PM
    can't you do it at group level?
    https://www.arubanetworks.com/techdocs/central/latest/content/aos10x/cfg/conf_ap1x_auth.htm

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------



  • 3.  RE: Configure Uplink Auth for all APs of a VC

    Posted Jun 10, 2022 03:11 AM
    On group level you can not configure the credentials. It even says so in the link you sent:


    So then I guess the only way is to create some script, because it isn't possible...

    ------------------------------
    Thanks,
    Bjarne
    ------------------------------



  • 4.  RE: Configure Uplink Auth for all APs of a VC

    Posted Jun 10, 2022 04:18 AM
    but with EAP-TLS it should be fine right?

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------



  • 5.  RE: Configure Uplink Auth for all APs of a VC

    Posted Jun 10, 2022 05:58 AM
    Then, when I upload the AP certificate in the global context as "server certificate", can I choose it in the AP as client certificate?
    Because I don't see a client certificate option in the upload certificate page:


    I saw that the APs need to be at least 8.9 for EAP-TLS in Central. 

    But the currently recommended version is 8.6.0.16



    We will upgrade in our test environment and test EAP-TLS Uplink auth on version 8.9

    ------------------------------
    Thanks,
    Bjarne
    ------------------------------